LlamaEmailBETA
Developer API

Integrate today.

One REST call to send from your domain. Mail lands in your mailbox, Sent folder, and Outlook — same place as webmail.

const res = await fetch('https://app.llamaemail.com/v1/emails', {
  method: 'POST',
  headers: {
    Authorization: `Bearer ${process.env.LLAMAEMAIL_API_KEY}`,
    'Content-Type': 'application/json',
    'Idempotency-Key': crypto.randomUUID(),
  },
  body: JSON.stringify({
    from: 'hello@yourdomain.com',
    to: 'friend@example.com',
    subject: 'Hello World',
    html: '<strong>It works.</strong>',
  }),
});

const email = await res.json();
console.log(email);

Authentication

Create a key in Settings → Developer API. Choose sending only, receive only, or full access. Keep keys on your server — never in browser JavaScript.

Authorization: Bearer le_live_<publicId>_<secret>
Access Scopes Allows
Sending only send POST /v1/emails
Receive only read GET /v1/emails, GET /v1/emails/{id}
Full access send + read Send and read

Send an email

Creates outbound mail through your mailbox. Accepted messages appear in webmail Sent.

POST https://app.llamaemail.com/v1/emails
Field Type Notes
from string Optional. Verified identity on the key’s mailbox.
to string | string[] Required.
cc, bcc string | string[] Optional.
subject string Optional.
text, html string At least one required. Max 100 KB each.
Idempotency-Key UUID header Safe retries. Also idempotency_key in JSON.

Attachments

Optional base64 attachments on send (max 30 files, 10 MB total).

{
  "attachments": [
    {
      "filename": "invoice.pdf",
      "content_type": "application/pdf",
      "content": "<base64>"
    }
  ]
}

List emails

Read inbox or sent for the key’s mailbox.

GET /v1/emails?folder=inbox&limit=20

Get an email

Fetch one message by id (64-character hex).

GET /v1/emails/{id}

Webhooks

Add an HTTPS endpoint in Settings → Developer API. We POST signed JSON for email.sent, email.bounced and email.complained.

LlamaEmail-Timestamp: 1717200000
LlamaEmail-Signature: <base64url hmac sha256 of timestamp.payload>

Verify with your signing secret: HMAC-SHA256 of timestamp + '.' + rawBody.

Errors

Errors return JSON shaped like { "error": { "message", "code" } }.

HTTP Code Meaning
401 unauthorized Missing or invalid API key
403 forbidden Missing scope, bad from, or sending suspended
409 conflict Idempotency key reused with a different payload
422 recipient_suppressed Recipient blocked after bounce/complaint
429 sending_limit Workspace send budget exceeded

OpenAPI

Machine-readable spec: /docs/api/openapi.json